Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

599 advisories

Loading
Craft CMS: Authenticated leak of secret environment variables Moderate
CVE-2026-72782 was published for craftcms/cms (Composer) Aug 6, 2026
SiYuan 3.8.0 contains a path traversal / sensitive file exposure vulnerability in the... Moderate Unreviewed
CVE-2026-82650 was published Aug 30, 2026
HTTP.sys Information Disclosure Vulnerability Moderate Unreviewed
CVE-2023-21687 was published Feb 14, 2023
Microsoft Office Information Disclosure Vulnerability Moderate Unreviewed
CVE-2023-21714 was published Feb 14, 2023
Azure Active Directory Information Disclosure Vulnerability Moderate Unreviewed
CVE-2021-42306 was published Nov 25, 2021
Electron: ProtocolResponse.url reuses the default session cache instead of the registering session Moderate
CVE-2026-70606 was published for electron (npm) Aug 5, 2026
rushitgit Credited to rushitgit
ViewComponent: Reused Component Instances Retain Stale Render Context Moderate
CVE-2026-54497 was published for view_component (RubyGems) Jul 15, 2026
cyberlanc3r Credited to cyberlanc3r
open-feature-operator: Cross-namespace FeatureFlagSource and InProcessConfiguration resolution exposes spec contents on multi-tenant clusters Moderate
CVE-2026-54495 was published for github.com/open-feature/open-feature-operator (Go) Jul 15, 2026
0xVijay Credited to 0xVijay
Steeltoe's static JWKS cache shared across schemes and never invalidated Moderate
CVE-2026-50202 was published for Steeltoe.Security.Authentication.CloudFoundryBase (NuGet) Jul 2, 2026
OpenClaw: Sandboxed session spawn could expose the real workspace path to child prompts Moderate
GHSA-6c4r-g249-wv3c was published for openclaw (npm) Jul 2, 2026
anshumanbh Credited to anshumanbh
TYPO3 ke_search path traversal from arbitrary table configuration input Moderate
CVE-2026-46723 was published for tpwd/ke_search (Composer) May 19, 2026
eliashaeussler Credited to eliashaeussler
PraisonAI has Memory State Leakage and Path Traversal in MultiAgent Context Handling Moderate
CVE-2026-56078 was published for praisonaiagents (pip) Apr 8, 2026
offset Credited to offset
NodeVM observability builtins leak host process and HTTP request data Moderate
CVE-2026-47141 was published for vm2 (npm) May 29, 2026
spbavarva Credited to spbavarva
j4xT Credited to j4xT
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false Moderate
CVE-2026-30912 was published for apache-airflow-core (pip) Apr 18, 2026
Apache Airflow has an authorization bypass in DagRun wait endpoint Moderate
CVE-2026-34538 was published for apache-airflow (pip) Apr 9, 2026
ProTip! Advisories are also available from the GraphQL API